Data processing statement and agreement
Posture does not send what your staff do in the app to us. There are no accounts, the apps send no analytics, and settings, history and health-check answers stay on each person's device. Sohus Ltd is not your processor for anything people do in the app. This page explains the data flows, then sets out the terms for the small amount of personal data we do handle: support emails, licence records, and the ordinary request logs our web host keeps.
What stays on the device
- Settings, break history and progress: in browser local storage for the web app, in macOS preferences for the Mac app, and in the app's data folder for the Windows app (or a "Posture data" folder next to the program for the portable version).
- Health-check answers: used on the device only, to leave out exercises that may not suit the person. They are never sent anywhere.
- Signals the desktop apps read to avoid interrupting people: time since the last keyboard or mouse input, whether the screen is locked, whether another app is using the camera or microphone, which app is in front and whether it is fullscreen, and (on Mac, only if the person turns it on) when calendar events start and end and whether they are marked busy. The apps never turn on the camera or microphone and record nothing. None of this leaves the device.
- Web app permissions: reminders use the browser's notification permission and, in Chrome and Edge, its idle-detection permission. Both stay on the device and can be turned off.
- No names, email addresses, keystrokes, window titles, screenshots, audio or video are collected or stored.
What goes over the network
The apps make only these requests, all to posturebreak.co.uk (posturebreak.vercel.app for Windows 0.3.0, Mac 0.3.4 and earlier):
| Request | When | What it contains |
|---|---|---|
Break-screen update check (Mac and Windows apps): /mac/version.json, and /mac/player.html when there is a new version | When the app starts, then about once a day. Also when someone chooses "Check for updates". | An ordinary web request. It carries no account, user ID, device ID or usage data. As with any web request, our host sees the device's IP address and the request details, including a user-agent that says it came from the Posture Mac or Windows app. Each download is checked against a SHA-256 hash before use, and anything that doesn't match is discarded. |
Optional guide figures (Sam, Nina, Marcus and Mei): /models/ | When someone has chosen one of these guides and it is needed. It may be downloaded again later, for example if a cache is cleared. | An ordinary file download, like loading a picture. Same request details as above. |
| The web app | When opened | Loads the app's files. It works offline after that. The app pages have no analytics. |
The apps send no analytics, crash reports or usage data.
Turning off network requests
Your IT team can set updates to 0 through Group Policy or Intune (Windows) or a configuration profile (Mac). The Mac and Windows apps then make no network requests except downloading a guide figure that someone chooses. To stop those downloads too, also set figure to m or f (the built-in guides Theo and Mia). You can also block the addresses above: Posture keeps working with the version it has and the built-in guides. See Deploying Posture.
The website
The website, web app and downloads are hosted by Vercel, which processes IP addresses and standard request logs for us to serve pages and keep the service secure. This includes the requests listed above. We don't use these logs to identify or track anyone. The home page, and only the home page, uses cookie-free Vercel Web Analytics to count visits. The app, the exercise guides and the other pages are not counted. See Privacy.
Pilot surveys
The before-and-after wellbeing survey in a pilot is run by you, in your own survey tool, not inside Posture. We don't receive individual answers. If you share results with us, please send only totals for groups of 10 or more people.
The agreement
This agreement is between Sohus Ltd (company number 09369062, registered in England and Wales, 167–169 Great Portland Street, 5th Floor, London W1W 5PF; ICO registration ZC111701) ("we", "us") and the organisation that holds a Posture for Work licence or runs a pilot ("you"). It applies alongside our terms of service and any quote or order you accept from us. If they conflict on data protection, this agreement wins.
1. Roles
- Use of the app. Data that Posture keeps on your devices is not sent to us, and we cannot access it. If any of it is personal data, how it is handled is a matter between you and your staff. We are neither a controller nor your processor for it.
- Our own records. We are the controller of our own business records: support correspondence, the licence and billing records we need to issue licences, invoice you and keep accounts, and the request logs our web host keeps for us. We handle them under the UK GDPR and the Data Protection Act 2018. This page is our privacy notice for that data.
- We do not currently act as your processor. If a future service means we process personal data on your behalf, we will agree processor terms with you that meet Article 28 of the UK GDPR before that processing starts.
2. What we handle
| Data | Why, and our lawful basis | How long |
|---|---|---|
| Support emails: the sender's name, email address, job title if given, and what they tell us | To answer questions and fix problems. Our legitimate interest in supporting customers. | As long as needed to resolve the matter and handle follow-up questions. Normally deleted within two years of the last message. |
| Licence records: organisation name, billing contact's name, email and address, number of people licensed, licence key, invoices and payments | To issue and renew licences and invoice you (performing our contract with you), and to keep the accounting records the law requires (legal obligation). | For the life of the licence, then as long as the law requires us to keep accounting records (normally six years) |
| Hosting request logs: IP address, time, the address requested and the user-agent, for the requests described above | To deliver the website, the web app, updates and guide figures, and keep them secure. Our legitimate interest in running the service. | Kept by Vercel for a limited period under its own log retention. We don't copy or combine them with other data. |
Please don't send us staff health information or other sensitive data in support requests. We don't need it to help you.
3. How we look after it
- We use this data only for the purposes above. We don't sell it, share it for marketing, or use it to profile anyone.
- Only people at Sohus Ltd who need it to provide support or billing can see it, and they are bound by confidentiality.
- We use reputable providers, protect access to our accounts with strong authentication, and use encrypted connections.
- The apps themselves are built so that there is no staff app data for us to hold: no accounts, no server of our own, and no analytics in the apps. Break-screen updates are hash-checked before use. See Security and data.
4. Providers we use
We are not your processor, so these are not sub-processors in the legal sense. They are the providers that handle the data in section 2 for us.
| Provider | What for |
|---|---|
| Vercel Inc. | Hosting the website, the web app and the downloads, including the update check. Processes IP addresses and request logs to serve them. |
| Our email provider | Sending and receiving support and billing email. We will name it on request. |
We will keep this list up to date, and tell your billing contact before we add or replace a provider that handles data in section 2.
5. International transfers
Vercel serves the website from a global network, so requests may be handled outside the UK. Where personal data goes outside the UK, we rely on a safeguard recognised by UK law, such as UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework, where the provider is certified) or the International Data Transfer Addendum to the EU standard contractual clauses. The same applies to our email provider.
6. Breaches
If we become aware of a personal data breach affecting data about your organisation or your staff, we will tell your billing or named contact without undue delay. We will say what happened, what data was involved and what we are doing about it, and give you reasonable help with any steps you need to take. Where the law requires it, we will report the breach to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it.
7. Information and audit
We will give you the information you reasonably need to check that this agreement is being followed, including answers to reasonable security questionnaires and details of our providers. Because we hold no app data about your staff, we meet audit requests with written information rather than on-site inspections, unless a regulator requires otherwise. We do not hold security certifications such as ISO 27001 or SOC 2.
8. People's rights
Anyone can ask us for a copy of the personal data we hold about them, or ask us to correct or delete it, restrict how we use it, or object to our using it, by emailing ben@immersi.co.uk. We will respond within one month. If a request is complex, we may take up to two more months and will tell the person why. We may need to keep some records, such as invoices, where the law requires it.
We cannot see or delete data on your devices. People can remove it themselves, or your IT team can, as set out in section 9.
9. When a licence or pilot ends
We delete support correspondence we no longer need, and keep licence and billing records only for as long as the law requires. You can ask us to confirm this in writing.
Data on your devices is yours to delete. Uninstalling does not always remove saved settings and history. To remove them:
- Windows: delete the
%APPDATA%\Posturefolder, or the "Posture data" folder for the portable version. - Mac: delete the app's preferences and its
~/Library/Application Support/Posturefolder. - Web app: clear the browser's site data for
posturebreak.co.uk, orposturebreak.vercel.appif that's where it was opened.
10. If we ever add optional usage reporting
Some organisations ask for take-up figures. If we ever add reporting like this, it will be off unless you choose to turn it on, and it will report only aggregate counts rather than anything about individuals. Before it becomes available, we will update this agreement, give you notice, and agree any processor terms needed under section 1.
11. Changes
We may update this agreement, for example to reflect a new provider or a change in the law. We will change the date at the top and tell your billing contact of any material change at least 30 days before it takes effect. If a change significantly affects you, it will apply from your next renewal unless you agree otherwise or the law requires it sooner.
12. Law
This agreement is governed by the law of England and Wales, and the courts of England and Wales have jurisdiction.
Contact
Questions about this agreement or data protection: ben@immersi.co.uk. Anyone can also complain to the Information Commissioner's Office at ico.org.uk.